Core Infrastructure and Security Blog

Options
1,662
Heinrich_Gantenbein on May 01 2024 08:47 AM
2,106
fbinotto on Apr 28 2024 11:45 PM
1,637
HoussemDellai on Apr 22 2024 09:00 AM
10.4K
Jerry Devore on Apr 15 2024 03:01 PM
3,427
WillAftring on Apr 08 2024 06:41 AM
3,464
BrandonWilson on Apr 06 2024 07:24 PM
2,229
PavelYurenev on Apr 04 2024 09:00 AM
5,008
hspinto on Apr 01 2024 12:00 AM
2,900
khgandhi on Mar 28 2024 09:46 AM
2,351
Bruno Gabrielli on Mar 21 2024 01:00 AM
15.3K
Paul Bergson on Mar 19 2024 04:30 AM
4,194
fbinotto on Mar 14 2024 01:30 AM
5,611
PaulHarrison on Mar 11 2024 03:00 AM
4,059
sairashaik on Mar 06 2024 06:01 PM
14.9K
Jerry Devore on Mar 04 2024 06:38 AM
25K
Jason Cody on Feb 29 2024 07:12 AM
4,542
jonasoh on Feb 26 2024 03:35 AM
3,007
BrandonWilson on Feb 21 2024 08:22 PM
37.1K
DagmarHeidecker on Feb 19 2024 04:15 AM
15.9K
BrandonWilson on Feb 18 2024 04:35 PM
5,673
Arnab Mitra on Feb 15 2024 11:59 AM
5,746
hspinto on Feb 12 2024 12:00 AM
15.8K
Paul Bergson on Feb 05 2024 04:13 AM
27.8K
Paul Bergson on Jan 29 2024 05:20 AM
3,929
Bindusar on Jan 23 2024 08:27 AM
7,029
Arnab Mitra on Jan 18 2024 08:50 AM
3,764
jonasoh on Jan 15 2024 03:31 AM
7,681
jonasoh on Jan 08 2024 05:18 AM
16K
BrandonWilson on Jan 07 2024 10:40 AM
6,227
Arnab Mitra on Jan 03 2024 01:39 PM

Latest Comments

if anyone knows any good/comprehensive kql queries for asset inventory I'd appreciate it.i.e. inclusive of all assets in defender for endpoint including workstations, servers, network devices etc.
0 Likes
JMSANTOS Copper Contributor‎Jun 10 2021 06:51 AM Any instructions about what to do with the MBAM client installed in the workstation? Should we uninstall it before we escrow the BitLocker recovery key? Once you backup the recovery keys to AD, you uninstall the client or you can wait till the BitLock...
0 Likes
in Protecting Tier 0 the Modern Way on May 12 2024 11:07 PM
Hello @NateBarkei , @ckuever0983 , can you validate the Kerberos amoring is enabled on this computer? Logon with a domain account and run klist and validate the TGT Cach Flags are 0x40 (FAST) enabled. If the FAST option is not enabled on the TGT validate the group policy settings ona) domain control...
0 Likes
in Protecting Tier 0 the Modern Way on May 11 2024 08:04 PM
Exactly the same problem as @ckuever0983 above. Brand new forest/domain (Server 2022) to test this out and always get: A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions. If this is working properly should event 4820 provide a device n...
0 Likes
Hello, i setup Legacy Microsoft LAPs when it came out but did not "fully deploy" it. i have tried since then to reverse it all and i did accomplish alot so far. i can now confirm that regular users cannot run to get passwords. i have removed the groups that i created to have "extended rights". my ad...
0 Likes